SonicWall has released patches to deal with three safety flaws affecting SMA 100 Safe Cell Entry (SMA) home equipment that may very well be normal to end in distant code execution.
The vulnerabilities are listed under –
- CVE-2025-32819 (CVSS rating: 8.8) – A vulnerability in SMA100 permits a distant authenticated attacker with SSL-VPN person privileges to bypass the trail traversal checks and delete an arbitrary file doubtlessly leading to a reboot to manufacturing facility default settings.
- CVE-2025-32820 (CVSS rating: 8.3) – A vulnerability in SMA100 permits a distant authenticated attacker with SSL-VPN person privileges can inject a path traversal sequence to make any listing on the SMA equipment writable
- CVE-2025-32821 (CVSS rating: 6.7) – A vulnerability in SMA100 permits a distant authenticated attacker with SSL-VPN admin privileges can with admin privileges can inject shell command arguments to add a file on the equipment
“An attacker with entry to an SMA SSL-VPN person account can chain these vulnerabilities to make a delicate system listing writable, elevate their privileges to SMA administrator, and write an executable file to a system listing,” Rapid7 said in a report. “This chain leads to root-level distant code execution.”
CVE-2025-32819 is assessed to be a patch bypass for a previously identified flaw reported by NCC Group in December 2021.
The cybersecurity firm famous that CVE-2025-32819 could have been exploited within the wild as a zero-day based mostly on identified indicators of compromise (IoCs) and incident response investigations. Nevertheless, it is price noting that SonicWall makes no point out of the flaw being weaponized in real-world assaults.
The shortcomings, that influence SMA 100 Collection together with SMA 200, 210, 400, 410, 500v, have been addressed in model 10.2.1.15-81sv.
The event comes as multiple security flaws in SMA 100 Collection gadgets have come beneath energetic exploitation in latest weeks, together with CVE-2021-20035, CVE-2023-44221, and CVE-2024-38475. Customers are suggested to replace their situations to the most recent model for optimum safety.
Source link